App Store Connect API keys are credentials. Apple says private keys can be downloaded only once and should be stored securely. Treat the file like a password with the ability to change app data.

Use the smallest role that supports the workflow. Keep the key in a secret store or protected environment, not in source control, screenshots, chat, or a client-side bundle.

Start with read-only checks. Confirm the key ID, issuer ID, and private key match. If a key is lost or exposed, revoke it and create a replacement.

Use this in your next ASO review

Turn the advice above into one small, traceable change. A simple review keeps your listing accurate and makes it easier to learn what helped.

  1. Open the current App Store Connect entry for your app and copy the App Store API key material you want to check.
  2. Compare it with the current product behavior, supported locales, and the source linked below.
  3. Draft one improvement, record the reason, and validate every field limit or submission rule that applies.
  4. Ask a person to approve the draft before it changes a live listing.